PatchSiren cyber security CVE debrief
CVE-2026-39501 RealMag777 CVE debrief
A Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FOX: from n/a through <= 1.4.5. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of RealMag777 FOX woocommerce-currency-switcher plugin for WordPress should verify their installation and update to a patched version if necessary. The CVE record was published on 2026-04-08T09:16:24.373Z and last modified on 2026-07-24T21:10:00.143Z.
- Vendor
- RealMag777
- Product
- FOX
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of RealMag777 FOX woocommerce-currency-switcher plugin for WordPress, security teams, and operators should verify their installation and update to a patched version if necessary. This vulnerability affects WordPress deployments using the FOX plugin, specifically version 1.4.5 and earlier.
Technical summary
The CVE-2026-39501 vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:24.373Z and last modified on 2026-07-24T21:10:00.143Z. The vulnerability is related to missing authorization in the RealMag777 FOX woocommerce-currency-switcher plugin. Affected users should verify their installation and update to a patched version if necessary.
Defensive priority
Medium priority due to the vulnerability's MEDIUM severity and potential impact on access control.
Recommended defensive actions
- Verify the version of RealMag777 FOX woocommerce-currency-switcher plugin and update to a patched version if necessary.
- Implement compensating controls to monitor and restrict access to sensitive areas of the plugin.
- Review and adjust access control configurations to prevent exploitation of incorrectly configured security levels.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record was published on 2026-04-08T09:16:24.373Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects FOX plugin for WordPress, specifically version 1.4.5 and earlier. Users should verify their installation and update to a patched version if necessary. Evidence of exploitation is limited, and defenders should verify the affected scope and severity.
Official resources
-
CVE-2026-39501 CVE record
CVE.org
-
CVE-2026-39501 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:24.373Z and has not been modified since then. The NVD entry is currently Deferred.